Google has rolled out Chrome 155 (155.0.8059.39/.40 for Windows and macOS, 155.0.8059.39 for Linux) with 247 security fixes — more than double the previous desktop release (108 in Chrome 154). SecurityWeek reported on 7 October 2026. Among them are four critical use-after-free flaws: CVE-2026-106382 (Chromecast), CVE-2026-106197 (Browser), CVE-2026-106358 (Navigation) and CVE-2026-106347 (Track). Google mentions no known in-the-wild exploitation, but four criticals — several potentially affecting sandbox boundaries — warrant rapid fleet update and restart.
CVE severity split is roughly 4 Critical, 53 High, 122 Medium and 68 Low. Common classes: incorrect authorization (41), use-after-free (34), missing authorization (34), UI misrepresentation (20), information leak (17) and uninitialized resource (16). External researchers reported 62 of the bugs; Google paid about $33,000 in bug bounties for the portion already disclosed, while amounts for nearly 50 reports are still pending.
A notable detail: researcher Xinyang Ge (Anthropic) authored many High/Critical reports, and several credit lines say "assisted by Claude". Two of the four criticals (Navigation and Track) were found with AI assistance. That mirrors a broader trend of AI-assisted vulnerability research accelerating discovery — in the same week LMCache and Atlassian PoCs dominate the news cycle.
For users and IT: the update “will roll out over the coming days/weeks”, so `chrome://settings/help` may be needed to force a check. In managed fleets, download alone is not enough — browsers must relaunch. Edge and other Chromium browsers often follow; inventory them separately. Even without reported wild exploitation, history shows Chrome criticals become targets quickly once details circulate.
Shipping 247 CVEs in one batch also strains patch communication: many organisations only prioritise “zero-day in the wild”. Here the wild signal is absent, but the volume plus four Critical UAFs — including Navigation/Browser — is enough to treat Chrome 155 as a mandatory same-week security window. AI-assisted findings also change the timeline: researchers can produce more High/Critical issues faster, making frequent rapid updates more important than quarterly image rebuilds.
For forensics and IR teams the browser remains a common initial-access path via drive-by and malicious documents. A fleet stuck on 154 after 155 ships leaves unnecessary attack surface just as Atlassian and supply-chain stories compete for the same SOC attention. Coordinate browser patching with other critical actions so “just Chrome” is not deferred to the weekend.
What IT and security leads should do now
Update Chrome to ≥155.0.8059.39 (Windows/Mac also .40) and verify relaunch on every client. In Intune/GPO/Jamf: track compliance and block older builds. Check Chromium-based side products. Prioritise machines browsing untrusted sites or holding high privileges. Tell users to fully quit and reopen the browser after update — otherwise critical UAFs remain in memory. Add a weekly-report check: share of clients on 155+ within 72 hours. Treat a missing relaunch as a missing patch in compliance reporting. Confirm auto-update is enabled for unmanaged endpoints where policy allows. Set a 72-hour SLA for critical browser patching in SOC runbooks and follow up on outlier OUs. Verify Chromebooks and VDI pools receive the same build, not only physical Windows clients.